ISO 27001
From compliance burden to certification, in a focused programme fitted to your organisation.
I built the compliance core of Secured by FM CyberSecurity, and I have taken Norwegian SMBs from zero to certification-ready in four to six weeks. ISO 27001 is a big job, but it does not have to be a slow one. What follows is the shape of a focused programme.
What we deliver
-
Gap analysis against ISO 27001:2022We walk the Annex A controls against today's operation and document which are missing, which exist informally, and which are ready for the auditor.
-
Statement of ApplicabilityAn SoA built on the real scope, with a written justification per control for inclusion or exclusion, not a template with your name pasted on top.
-
ISMS documentationPolicies, procedures, and roles written for your organisation, not for the auditor. We own the template set and keep it alive between audits.
-
Control implementation with technical ownersEvery control gets a named customer-side owner and a concrete action plan, tied to the technical practices FM CyberSecurity already operates.
-
Internal audit and management reviewWe run the internal audit, document findings, and prepare the management review so the minutes are ready before the certification auditor arrives.
-
A GRC tool that keeps controls aliveWe set up Kertos or ServiceNow GRC so evidence accrues continuously, not as a panic sprint the week before the auditor shows up.
How we deliver this service
- In a project
A certification programme with a fixed scope, from gap analysis through the certification audit.
- As part of a service
Included in the Secured by FM CyberSecurity bundle with a certification guarantee, a refund if you do not pass the certification audit within the agreed window.
- In a role at the customer
An ISMS owner as a dedicated seat inside your organisation when the controls need to live on after certification.
Recent insights on ISO 27001
- How long does ISO 27001 take?
The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.
- How we use AI to get SMBs certification-ready in four to six weeks
AI drafts the documentation, our consultants adapt it with you, and the evidence gathers itself in a GRC tool. That is how the timeline holds up.
- ISO 27001 or NIS2 first?
A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.